From 7d3abc73c6bddab56a4992e8036bcfc691fb6a03 Mon Sep 17 00:00:00 2001 From: Brent Shaffer Date: Thu, 17 Sep 2026 00:25:08 +0000 Subject: [PATCH 1/5] chore: refactor pnpm lockfile check and add --ignore-scripts --- .../actions/pnpm-lockfile-check/action.yaml | 26 +++++++++++++++++++ .github/actions/run-unit-tests/action.yaml | 22 +--------------- .github/workflows/bigtable-conformance.yaml | 21 +-------------- .github/workflows/continuous.yaml | 21 +-------------- .github/workflows/mandatory-conformance.yaml | 21 +-------------- .github/workflows/presubmit-bun.yml | 21 +-------------- .github/workflows/presubmit.yaml | 21 +-------------- .github/workflows/storage-conformance.yaml | 21 +-------------- 8 files changed, 33 insertions(+), 141 deletions(-) create mode 100644 .github/actions/pnpm-lockfile-check/action.yaml diff --git a/.github/actions/pnpm-lockfile-check/action.yaml b/.github/actions/pnpm-lockfile-check/action.yaml new file mode 100644 index 00000000000..12342aa91a2 --- /dev/null +++ b/.github/actions/pnpm-lockfile-check/action.yaml @@ -0,0 +1,26 @@ +name: "Check PNPM Lockfile and Install Workspace Dependencies" +description: "Sets up pnpm and installs workspace dependencies with frozen lockfile check" +runs: + using: "composite" + steps: + - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 + - name: Install Workspace Dependencies (Frozen Lockfile) + shell: bash + run: | + if ! pnpm install --frozen-lockfile --ignore-scripts; then + echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." + echo "" + echo "====================================================================================================" + echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" + echo "" + echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." + echo "" + echo "To resolve this failure, please update the lockfile locally and commit the result:" + echo " pnpm install --no-frozen-lockfile --ignore-scripts" + echo " git add pnpm-lock.yaml" + echo " git commit -m \"chore: update pnpm-lock.yaml\"" + echo " git push" + echo "====================================================================================================" + echo "" + exit 1 + fi diff --git a/.github/actions/run-unit-tests/action.yaml b/.github/actions/run-unit-tests/action.yaml index 8756c30c924..b9c32156528 100644 --- a/.github/actions/run-unit-tests/action.yaml +++ b/.github/actions/run-unit-tests/action.yaml @@ -17,27 +17,7 @@ runs: uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: ${{ inputs.node-version }} - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - - name: Install Workspace Dependencies (Frozen Lockfile) - run: | - if ! pnpm install --frozen-lockfile --ignore-scripts; then - echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" - echo "" - echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." - echo "" - echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi - shell: bash + - uses: ./.github/actions/pnpm-lockfile-check - name: Cache Turborepo uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 with: diff --git a/.github/workflows/bigtable-conformance.yaml b/.github/workflows/bigtable-conformance.yaml index a4adbc1fb04..0d4bf4ee29a 100644 --- a/.github/workflows/bigtable-conformance.yaml +++ b/.github/workflows/bigtable-conformance.yaml @@ -52,26 +52,7 @@ jobs: with: go-version: '>=1.20.2' - run: chmod +x .kokoro/conformance.sh - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - - name: Install Workspace Dependencies (Frozen Lockfile) - run: | - if ! pnpm install --frozen-lockfile --ignore-scripts; then - echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" - echo "" - echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." - echo "" - echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi + - uses: ./.github/actions/pnpm-lockfile-check - run: pnpm --filter ...{handwritten/bigtable} run --if-present compile - run: go version - run: .kokoro/conformance.sh diff --git a/.github/workflows/continuous.yaml b/.github/workflows/continuous.yaml index 08d179d4fac..2c844e2e60f 100644 --- a/.github/workflows/continuous.yaml +++ b/.github/workflows/continuous.yaml @@ -20,26 +20,7 @@ jobs: uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: ${{ matrix.node }} - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - - name: Install Workspace Dependencies (Frozen Lockfile) - run: | - if ! pnpm install --frozen-lockfile --ignore-scripts; then - echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" - echo "" - echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." - echo "" - echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi + - uses: ./.github/actions/pnpm-lockfile-check - run: node --version - run: ci/run_conditional_tests.sh name: Run unit tests diff --git a/.github/workflows/mandatory-conformance.yaml b/.github/workflows/mandatory-conformance.yaml index 12c0ca9266c..d6caf0830a5 100644 --- a/.github/workflows/mandatory-conformance.yaml +++ b/.github/workflows/mandatory-conformance.yaml @@ -52,26 +52,7 @@ jobs: with: go-version: '>=1.20.2' - run: chmod +x .kokoro/mandatory-conformance.sh - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - - name: Install Workspace Dependencies (Frozen Lockfile) - run: | - if ! pnpm install --frozen-lockfile --ignore-scripts; then - echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" - echo "" - echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." - echo "" - echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi + - uses: ./.github/actions/pnpm-lockfile-check - run: pnpm --filter ...{handwritten/bigtable} run --if-present compile - run: go version - run: .kokoro/mandatory-conformance.sh diff --git a/.github/workflows/presubmit-bun.yml b/.github/workflows/presubmit-bun.yml index 3543f8f6ab5..b5006cf8a93 100644 --- a/.github/workflows/presubmit-bun.yml +++ b/.github/workflows/presubmit-bun.yml @@ -36,26 +36,7 @@ jobs: uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: ${{ matrix.node-version }} - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - - name: Install Workspace Dependencies (Frozen Lockfile) - run: | - if ! pnpm install --frozen-lockfile --ignore-scripts; then - echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" - echo "" - echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." - echo "" - echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi + - uses: ./.github/actions/pnpm-lockfile-check - name: Cache Turborepo uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 with: diff --git a/.github/workflows/presubmit.yaml b/.github/workflows/presubmit.yaml index 4f44111d5ee..bcbc2ae0347 100644 --- a/.github/workflows/presubmit.yaml +++ b/.github/workflows/presubmit.yaml @@ -48,26 +48,7 @@ jobs: uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: 24 - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - - name: Install Workspace Dependencies (Frozen Lockfile) - run: | - if ! pnpm install --frozen-lockfile --ignore-scripts; then - echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" - echo "" - echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." - echo "" - echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi + - uses: ./.github/actions/pnpm-lockfile-check - name: Cache Turborepo uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 with: diff --git a/.github/workflows/storage-conformance.yaml b/.github/workflows/storage-conformance.yaml index 7e27fc24cc4..3a1fd0d5236 100644 --- a/.github/workflows/storage-conformance.yaml +++ b/.github/workflows/storage-conformance.yaml @@ -22,25 +22,6 @@ jobs: with: node-version: 22 - run: node --version - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - - name: Install Workspace Dependencies (Frozen Lockfile) - run: | - if ! pnpm install --frozen-lockfile --ignore-scripts; then - echo "::error title=PNPM Lockfile Out of Date::The pnpm-lock.yaml file is out of sync with workspace package.json dependencies." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Lockfile Out of Date (ERR_PNPM_OUTDATED_LOCKFILE)" - echo "" - echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." - echo "" - echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi + - uses: ./.github/actions/pnpm-lockfile-check - run: pnpm --filter ...{handwritten/storage} run --if-present compile - run: cd handwritten/storage && pnpm run conformance-test From 57fa7096d6cbcb4e3df7d911255875e8fdac1aa5 Mon Sep 17 00:00:00 2001 From: Brent Shaffer Date: Wed, 23 Sep 2026 17:07:45 +0000 Subject: [PATCH 2/5] chore: recommend pnpm install --lockfile-only in lockfile check --- .github/actions/pnpm-lockfile-check/action.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/actions/pnpm-lockfile-check/action.yaml b/.github/actions/pnpm-lockfile-check/action.yaml index 12342aa91a2..dbc9ad85e54 100644 --- a/.github/actions/pnpm-lockfile-check/action.yaml +++ b/.github/actions/pnpm-lockfile-check/action.yaml @@ -16,7 +16,7 @@ runs: echo "One or more package.json files have changed or were merged without updating pnpm-lock.yaml." echo "" echo "To resolve this failure, please update the lockfile locally and commit the result:" - echo " pnpm install --no-frozen-lockfile --ignore-scripts" + echo " pnpm install --lockfile-only" echo " git add pnpm-lock.yaml" echo " git commit -m \"chore: update pnpm-lock.yaml\"" echo " git push" From feafe5fc9b4c6d6bf989490719f466f9c042f338 Mon Sep 17 00:00:00 2001 From: Brent Shaffer Date: Wed, 23 Sep 2026 17:15:17 +0000 Subject: [PATCH 3/5] chore(ci): recommend pnpm install --lockfile-only in run_single_test.sh --- ci/run_single_test.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ci/run_single_test.sh b/ci/run_single_test.sh index 8a03dfa4ff7..e99b23fab96 100755 --- a/ci/run_single_test.sh +++ b/ci/run_single_test.sh @@ -59,7 +59,7 @@ if ! pnpm install --engine-strict --pnpmfile "${PNPMFILE_PATH}"; then echo "❌ PNPM Install Failed" echo "" echo "If this failure is caused by an outdated lockfile or changed package.json dependencies, run:" - echo " pnpm install --no-frozen-lockfile" + echo " pnpm install --lockfile-only" echo " git add pnpm-lock.yaml" echo " git commit -m \"chore: update pnpm-lock.yaml\"" echo " git push" From cf6f547bdbdced0c059a1dd6ee814f8a975a0e1f Mon Sep 17 00:00:00 2001 From: Brent Shaffer Date: Wed, 23 Sep 2026 17:44:04 +0000 Subject: [PATCH 4/5] fix(ci): compile missing build output in run_single_test.sh and run smoke test on ci changes --- ci/run_conditional_tests.sh | 10 ++++++++-- ci/run_single_test.sh | 38 ++++++++++++++++++++++--------------- 2 files changed, 31 insertions(+), 17 deletions(-) diff --git a/ci/run_conditional_tests.sh b/ci/run_conditional_tests.sh index 36e00d66c0f..ab581afbdc7 100755 --- a/ci/run_conditional_tests.sh +++ b/ci/run_conditional_tests.sh @@ -102,6 +102,7 @@ fi # Then detect changes in the test scripts. +CI_CHANGED=false set +e git diff --quiet ${GIT_DIFF_ARG} ci changed=$? @@ -109,10 +110,10 @@ set -e if [[ "${changed}" -eq 0 ]]; then echo "no change detected in ci" else - echo "change detected in ci, we should test everything" + echo "change detected in ci, running representative smoke test" echo "result of git diff ${GIT_DIFF_ARG} ci:" git diff ${GIT_DIFF_ARG} ci - GIT_DIFF_ARG="" + CI_CHANGED=true fi # Now we have a fixed list, but we can change it to autodetect if @@ -265,6 +266,11 @@ for subdir in ${subdirs[@]}; do fi done done + +if [[ "${CI_CHANGED}" == "true" && ${#test_dirs[@]} -eq 0 ]]; then + test_dirs+=("packages/google-cloud-kms/") +fi + # If RUN_TESTS_MODE is CALCULATE_SHARD_MATRIX, output dynamic matrix values to GitHub Actions and exit if [[ "${RUN_TESTS_MODE}" == "CALCULATE_SHARD_MATRIX" ]]; then count=${#test_dirs[@]} diff --git a/ci/run_single_test.sh b/ci/run_single_test.sh index e99b23fab96..fd878d0f745 100755 --- a/ci/run_single_test.sh +++ b/ci/run_single_test.sh @@ -51,21 +51,29 @@ if command -v cygpath >/dev/null 2>&1; then PNPMFILE_PATH=$(cygpath -m "${PNPMFILE_PATH}") fi -echo "pnpm install --engine-strict --pnpmfile \"${PNPMFILE_PATH}\"" -if ! pnpm install --engine-strict --pnpmfile "${PNPMFILE_PATH}"; then - echo "::error title=PNPM Install Failed::pnpm install failed in $(pwd)." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Install Failed" - echo "" - echo "If this failure is caused by an outdated lockfile or changed package.json dependencies, run:" - echo " pnpm install --lockfile-only" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 +if [ ! -d "node_modules" ]; then + echo "pnpm install --engine-strict --pnpmfile \"${PNPMFILE_PATH}\"" + if ! pnpm install --engine-strict --pnpmfile "${PNPMFILE_PATH}"; then + echo "::error title=PNPM Install Failed::pnpm install failed in $(pwd)." + echo "" + echo "====================================================================================================" + echo "❌ PNPM Install Failed" + echo "" + echo "If this failure is caused by an outdated lockfile or changed package.json dependencies, run:" + echo " pnpm install --lockfile-only" + echo " git add pnpm-lock.yaml" + echo " git commit -m \"chore: update pnpm-lock.yaml\"" + echo " git push" + echo "====================================================================================================" + echo "" + exit 1 + fi +fi + +if [ ! -d "build" ] && [ "${TEST_TYPE}" != "lint" ]; then + if grep -q '"compile":' package.json; then + ${TEST_CMD} compile + fi fi From dbc26dc881fabbd6553f45dbb7f5ca561a1d5396 Mon Sep 17 00:00:00 2001 From: Brent Shaffer Date: Wed, 23 Sep 2026 17:56:25 +0000 Subject: [PATCH 5/5] revert(ci): remove ci script changes from PR --- ci/run_conditional_tests.sh | 10 ++-------- ci/run_single_test.sh | 38 +++++++++++++++---------------------- 2 files changed, 17 insertions(+), 31 deletions(-) diff --git a/ci/run_conditional_tests.sh b/ci/run_conditional_tests.sh index ab581afbdc7..36e00d66c0f 100755 --- a/ci/run_conditional_tests.sh +++ b/ci/run_conditional_tests.sh @@ -102,7 +102,6 @@ fi # Then detect changes in the test scripts. -CI_CHANGED=false set +e git diff --quiet ${GIT_DIFF_ARG} ci changed=$? @@ -110,10 +109,10 @@ set -e if [[ "${changed}" -eq 0 ]]; then echo "no change detected in ci" else - echo "change detected in ci, running representative smoke test" + echo "change detected in ci, we should test everything" echo "result of git diff ${GIT_DIFF_ARG} ci:" git diff ${GIT_DIFF_ARG} ci - CI_CHANGED=true + GIT_DIFF_ARG="" fi # Now we have a fixed list, but we can change it to autodetect if @@ -266,11 +265,6 @@ for subdir in ${subdirs[@]}; do fi done done - -if [[ "${CI_CHANGED}" == "true" && ${#test_dirs[@]} -eq 0 ]]; then - test_dirs+=("packages/google-cloud-kms/") -fi - # If RUN_TESTS_MODE is CALCULATE_SHARD_MATRIX, output dynamic matrix values to GitHub Actions and exit if [[ "${RUN_TESTS_MODE}" == "CALCULATE_SHARD_MATRIX" ]]; then count=${#test_dirs[@]} diff --git a/ci/run_single_test.sh b/ci/run_single_test.sh index fd878d0f745..8a03dfa4ff7 100755 --- a/ci/run_single_test.sh +++ b/ci/run_single_test.sh @@ -51,29 +51,21 @@ if command -v cygpath >/dev/null 2>&1; then PNPMFILE_PATH=$(cygpath -m "${PNPMFILE_PATH}") fi -if [ ! -d "node_modules" ]; then - echo "pnpm install --engine-strict --pnpmfile \"${PNPMFILE_PATH}\"" - if ! pnpm install --engine-strict --pnpmfile "${PNPMFILE_PATH}"; then - echo "::error title=PNPM Install Failed::pnpm install failed in $(pwd)." - echo "" - echo "====================================================================================================" - echo "❌ PNPM Install Failed" - echo "" - echo "If this failure is caused by an outdated lockfile or changed package.json dependencies, run:" - echo " pnpm install --lockfile-only" - echo " git add pnpm-lock.yaml" - echo " git commit -m \"chore: update pnpm-lock.yaml\"" - echo " git push" - echo "====================================================================================================" - echo "" - exit 1 - fi -fi - -if [ ! -d "build" ] && [ "${TEST_TYPE}" != "lint" ]; then - if grep -q '"compile":' package.json; then - ${TEST_CMD} compile - fi +echo "pnpm install --engine-strict --pnpmfile \"${PNPMFILE_PATH}\"" +if ! pnpm install --engine-strict --pnpmfile "${PNPMFILE_PATH}"; then + echo "::error title=PNPM Install Failed::pnpm install failed in $(pwd)." + echo "" + echo "====================================================================================================" + echo "❌ PNPM Install Failed" + echo "" + echo "If this failure is caused by an outdated lockfile or changed package.json dependencies, run:" + echo " pnpm install --no-frozen-lockfile" + echo " git add pnpm-lock.yaml" + echo " git commit -m \"chore: update pnpm-lock.yaml\"" + echo " git push" + echo "====================================================================================================" + echo "" + exit 1 fi